Phone Hack Used to Drain Bank Accounts

A known security hole in the networking protocol used by cellphone providers around the world became a tool for attack that drains bank customer accounts.

The weakness is the Signalling System No. 7, used by more than 800 telcos around the world to make sure that things work when you’re roaming, on a train, texting your friend overseas. Thing is, the same system can be used to eavesdrop on conversations, track geographic whereabouts, or intercept text messages.

Looks like this method is used by hackers to bypass two-factor authentication that many banks use, to prevent unauthorised withdrawals from online accounts.

ArsTechnica explained this in more detail:

“Specifically, the attackers used SS7 to redirect the text messages the banks used to send one-time passwords. Instead of being delivered to the phones of designated account holders, the text messages were diverted to numbers controlled by the attackers. The attackers then used the mTANs—short for “mobile transaction authentication numbers”—to transfer money out of the accounts.”

This isn’t new. This vulnerability has been known since 2008, but awareness is still limited. Many Malaysian banks are still relying on 2 factor authentication to secure bank accounts, and there has been a call for banks to adopt for more secure approach apart from using OTP (one time PIN) sent to a phone number.

It could take years to fully secure the system, or migrate to an alternative solution. Until then, the next best option really is using encrypted messaging services.

Comment what you think!